Apple patches urgent security flaw affecting iOS 26, iPadOS 26 and macOS 26 devices
Apple has released an urgent security fix for iOS 26, iPadOS 26 and macOS 26 after a bug that may have been exploited in sophisticated attacks against targeted individuals. Nearly 80% of iPhone users still run the affected version.

Apple has fixed a security vulnerability in iOS 26, iPadOS 26 and macOS 26 that the company says may have already been exploited by hackers. According to Apple, the flaw could have enabled an extremely sophisticated attack against specific targeted individuals on devices running versions prior to iOS 27.
According to Apple's security page, the bug was located in the core graphics engine responsible for powering the user interface and visuals on iPhones, iPads and Macs. The discovery is credited to Meta's product security team. Technical details of the flaw, officially designated CVE-2026-86950, have not been disclosed, but a device's graphics engine typically has broad access to the rest of the operating system, meaning a successful exploit could allow an attacker to steal a wide range of personal data.
Spokespeople for Apple and Meta did not comment when asked how the bug was discovered or how many devices, if any, had been compromised as a result. It also remains unclear who might be exploiting the vulnerability, whether government spyware vendors or cybercriminals.
Although the flaw affects Apple's previous generation of operating systems, that software remains widely used — nearly four in five iPhone owners are still running iOS 26, according to Apple's own figures. Devices running the newer iOS 27, iPadOS 27 and macOS 27, released earlier this month, also received an update on Tuesday but are not affected by this particular bug.
A separate zero-click bug also fixed
The patch follows Apple's recent fix for another critical flaw, CVE-2026-86869, which could have let hackers silently extract data from affected iPhones, iPads and Macs. Belgian cybersecurity firm ironPeak published a detailed report last week describing the issue as a "zero-click" vulnerability that could be triggered invisibly through a maliciously crafted iMessage, without any action from the user.
Such vulnerabilities require no victim interaction and are highly valued by surveillance and spyware vendors. The bug was capable of bypassing BlastDoor, the security feature Apple built to stop malicious code from escaping iMessage's sandbox. Apple resolved the issue in September with the release of iOS 27, iPadOS 27 and macOS 27, crediting ironPeak researcher Niels Hofmans along with security researchers at Meta for the discovery.
